AdroitPad

TECHNICAL TRUST

What leaves your machine?

AdroitPad is local-first. Here is the complete list: update checks, licence validation, on-demand developer news, an AI model if you choose one, the APIs you point the client at, your own cloud AI provider only if you add a key, your email if you ask for updates, a contact form only if you send one, and one hashed trial check. Nothing else.

The trial check

Once per installation, AdroitPad sends a salted one-way hash of the OS machine identifier plus the app version. The hash is computed on the machine and cannot be reversed by us. The stored row is that hash and a date. If the request fails or is blocked, the app starts the trial locally and opens anyway.

How data is stored

A single encrypted database uses AES-256. The key is held in your OS keychain: macOS Keychain, Windows DPAPI or Linux libsecret. The app auto-locks on idle, with Touch ID on macOS and a passcode elsewhere.

Secrets and AI

Known AWS, GitHub, Slack, Google and Stripe tokens, private keys, .env blocks and connection strings are masked, excluded from search and excluded from AI. Clipboard contents clear after 30 seconds. The local AI has no email, HTTP, upload or share tool.

Honest limits

AdroitPad is not audited and holds no compliance certification. Encryption protects data at rest. If your machine is compromised while the vault is unlocked, so is your data.

Security reports: privacy@adroitpad.com